panchoz ha scritto:sorpresa ha scritto:panchoz ha scritto:O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
Non può essere "disabilitato" d'ufficio!
Purtroppo, bisogna disinstallare Spybot S&D e reinstallarlo facendo attenzione a togliere la spunta su "Tea Timer" in fase d'installazione.
Grazie ora non ho tempo ma proverò con combofix, prima di cancellare qualcosa però aspetto ciao a domani
Te l'ho scritto nel 1° post, segui le istruzioni di A. Roselli, Pidue, R16 e paolopa quando si tratta di operazioni che possono compromettere il pc.
ALLEGO ANCHE IL LOG DI COMBOFIX CONTROLLATE ANCHE QUESTO OLTRE AL RESTO PER FAVORE...GRAZIE?ComboFix 10-07-19.05 - 20.17.12.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.1023.543 [GMT 2:00]
Eseguito da: d:\documents and settings\\Desktop\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
d:\windows\system32\msconfig.exe
.
((((((((((((((((((((((((( Files Creati Da 2010-06-20 al 2010-07-20 )))))))))))))))))))))))))))))))))))
.
2010-07-10 22:18 . 2010-07-10 22:18 -------- d-----w- d:\documents and settings\GIANNI\Dati applicazioni\DivX
2010-06-29 06:55 . 2010-06-28 20:57 38848 ----a-w- d:\windows\avastSS.scr
2010-06-21 13:18 . 2010-06-21 13:18 50354 ----a-w- d:\documents and settings\Pazzia Mia\Dati applicazioni\Facebook\uninstall.exe
2010-06-21 13:18 . 2010-06-21 13:18 -------- d-----w- d:\documents and settings\Pazzia Mia\Dati applicazioni\Facebook
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-20 16:01 . 2010-02-17 10:32 -------- d-----w- d:\programmi\LogMeIn
2010-07-19 13:24 . 2010-03-22 20:12 -------- d---a-w- d:\documents and settings\All Users\Dati applicazioni\TEMP
2010-07-19 13:24 . 2010-04-18 11:53 -------- d-----w- d:\programmi\SpywareBlaster
2010-07-19 06:44 . 2010-02-18 12:37 1 ----a-w- d:\documents and settings\GIANNI\Dati applicazioni\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-07-12 17:25 . 2010-02-16 17:32 -------- d-----w- d:\documents and settings\GIANNI\Dati applicazioni\vlc
2010-07-10 08:48 . 2010-03-11 05:28 1 ----a-w- d:\documents and settings\Pazzia Mia\Dati applicazioni\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-06-30 19:32 . 2001-08-31 12:00 84504 ----a-w- d:\windows\system32\perfc010.dat
2010-06-30 19:32 . 2001-08-31 12:00 489742 ----a-w- d:\windows\system32\perfh010.dat
2010-06-28 20:57 . 2010-02-16 16:17 165032 ----a-w- d:\windows\system32\aswBoot.exe
2010-06-28 20:37 . 2010-02-16 16:17 46672 ----a-w- d:\windows\system32\drivers\aswTdi.sys
2010-06-28 20:37 . 2010-02-16 16:17 165456 ----a-w- d:\windows\system32\drivers\aswSP.sys
2010-06-28 20:33 . 2010-02-16 16:17 23376 ----a-w- d:\windows\system32\drivers\aswRdr.sys
2010-06-28 20:32 . 2010-02-16 16:17 100176 ----a-w- d:\windows\system32\drivers\aswmon2.sys
2010-06-28 20:32 . 2010-02-16 16:17 94544 ----a-w- d:\windows\system32\drivers\aswmon.sys
2010-06-28 20:32 . 2010-02-16 16:17 17744 ----a-w- d:\windows\system32\drivers\aswFsBlk.sys
2010-06-28 20:32 . 2010-02-16 16:17 28880 ----a-w- d:\windows\system32\drivers\aavmker4.sys
2010-06-24 12:38 . 2010-03-07 19:54 26336 ----a-w- d:\documents and settings\Pazzia Mia\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2010-06-17 18:25 . 2010-04-07 19:12 -------- d-----w- d:\documents and settings\Pazzia Mia\Dati applicazioni\vlc
2010-06-16 10:56 . 2010-02-17 18:01 15880 ----a-w- d:\windows\system32\lsdelete.exe
2010-06-11 11:01 . 2010-02-17 10:32 83360 ----a-w- d:\windows\system32\LMIRfsClientNP.dll
2010-06-11 11:01 . 2010-02-17 10:32 29568 ----a-w- d:\windows\system32\LMIport.dll
2010-06-11 11:01 . 2010-02-17 10:32 87424 ----a-w- d:\windows\system32\LMIinit.dll
2010-06-10 05:00 . 2010-02-17 10:50 -------- d-----w- d:\programmi\Microsoft Silverlight
2010-06-09 10:45 . 2010-06-09 10:45 5591040 ----a-w- d:\documents and settings\Pazzia Mia\Dati applicazioni\Facebook\npfbplugin_1_0_3.dll
2010-06-09 04:41 . 2010-06-09 04:41 -------- d-----w- d:\programmi\FreeTime
2010-06-08 17:23 . 2010-02-28 15:12 -------- d-----w- d:\documents and settings\GIANNI\Dati applicazioni\dvdcss
2010-06-05 08:49 . 2010-02-17 10:43 64288 ----a-w- d:\windows\system32\drivers\Lbd.sys
2010-06-03 16:53 . 2010-02-16 15:46 26336 ----a-w- d:\documents and settings\GIANNI\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2010-05-31 19:08 . 2010-05-31 19:08 -------- d-----w- d:\programmi\ASIO4ALL v2
2010-05-31 19:08 . 2010-05-31 19:07 -------- d-----w- d:\programmi\VstPlugins
2010-05-31 19:08 . 2010-05-31 19:04 -------- d-----w- d:\programmi\Image-Line
2010-05-31 19:07 . 2010-05-31 19:07 -------- d-----w- d:\programmi\Outsim
2010-05-26 20:07 . 2010-05-26 20:03 -------- d-----w- d:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2010-05-19 15:33 . 2010-05-19 15:33 1956808 ----a-w- d:\documents and settings\Pazzia Mia\Dati applicazioni\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2010-05-05 14:45 . 2010-04-06 17:17 443912 ----a-w- d:\documents and settings\GIANNI\Dati applicazioni\Real\Update\setup3.10\setup.exe
2010-05-05 14:40 . 2010-05-05 14:39 442368 ----a-w- d:\documents and settings\GIANNI\Dati applicazioni\Real\Update\setup3.10\rp\RealPlayerSPGold_it.exe
2010-05-04 17:16 . 2008-03-01 12:58 832512 ----a-w- d:\windows\system32\wininet.dll
2010-05-04 17:15 . 2008-05-10 13:14 78336 ----a-w- d:\windows\system32\ieencode.dll
2010-05-04 17:15 . 2008-05-10 13:13 17408 ----a-w- d:\windows\system32\corpol.dll
2010-05-02 08:06 . 2008-04-13 16:50 1851264 ----a-w- d:\windows\system32\win32k.sys
2010-04-29 13:39 . 2010-04-15 16:27 38224 ----a-w- d:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 13:39 . 2010-04-15 16:27 20952 ----a-w- d:\windows\system32\drivers\mbam.sys
2010-04-26 16:09 . 2010-04-26 16:09 388096 ----a-r- d:\documents and settings\GIANNI\Dati applicazioni\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
.
------- Sigcheck -------
[-] 2008-05-10 . 1428D11D3408973FC5DFAE8FDCFFB87F . 1571840 . . [5.1.2600.5512] . . d:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="d:\programmi\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
"X'nBeep"="d:\programmi\X'nBeep 1.1\XnBeep.exe" [2007-01-08 1067520]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="d:\programmi\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"avast5"="d:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]
"Adobe Reader Speed Launcher"="d:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="d:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"iTunesHelper"="d:\programmi\iTunes\iTunesHelper.exe" [2010-01-22 141608]
"LogMeIn GUI"="d:\programmi\LogMeIn\x86\LogMeInSystray.exe" [2008-08-11 63048]
"SunJavaUpdateSched"="d:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-01-11 246504]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
"MsnMsgr"="d:\programmi\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
"nltide_3"="advpack.dll" [2010-05-04 124928]
d:\documents and settings\Pazzia Mia\Menu Avvio\Programmi\Esecuzione automatica\
OpenOffice.org 3.2.lnk - d:\programmi\OpenOffice.org 3\program\quickstart.exe [2009-12-15 384000]
d:\documents and settings\GIANNI\Menu Avvio\Programmi\Esecuzione automatica\
OpenOffice.org 3.2.lnk - d:\programmi\OpenOffice.org 3\program\quickstart.exe [2009-12-15 384000]
d:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
Adobe Gamma Loader.exe.lnk - d:\programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe [2010-3-4 113664]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2010-06-11 11:01 87424 ----a-w- d:\windows\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"TkBellExe"="d:\programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
"QuickTime Task"="d:\programmi\QuickTime\QTTask.exe" -atboottime
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"d:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"d:\\Programmi\\iTunes\\iTunes.exe"=
"d:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"d:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Programmi\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"d:\\Programmi\\eMule\\LinkCreator.exe"=
"d:\\Programmi\\eMule\\emule.exe"=
R0 Lbd;Lbd;d:\windows\system32\drivers\Lbd.sys [17/02/2010 12.43.10 64288]
R0 pssnap;Paramount Software Snapshot Filter;d:\windows\system32\drivers\pssnap.sys [28/01/2010 17.12.32 15328]
R1 aswSP;aswSP;d:\windows\system32\drivers\aswSP.sys [16/02/2010 18.17.41 165456]
R2 aswFsBlk;aswFsBlk;d:\windows\system32\drivers\aswFsBlk.sys [16/02/2010 18.17.42 17744]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;d:\programmi\Lavasoft\Ad-Aware\AAWService.exe [04/02/2010 17.52.57 1352832]
R2 LMIInfo;LogMeIn Kernel Information Provider;d:\programmi\LogMeIn\x86\rainfo.sys [11/08/2008 13.41.00 12856]
R2 ReflectService;Macrium Reflect Image Mounting Service;d:\programmi\Macrium\Reflect\ReflectService.exe [28/01/2010 17.12.12 220128]
S2 gupdate;Servizio di Google Update (gupdate);d:\programmi\Google\Update\GoogleUpdate.exe [16/02/2010 18.14.25 135664]
S3 PSMounter;Macrium Reflect Image Explorer Service;d:\windows\system32\drivers\psmounter.sys [28/01/2010 17.12.22 32736]
.
Contenuto della cartella 'Scheduled Tasks'
2010-04-22 d:\windows\Tasks\GlaryInitialize.job
- d:\programmi\Glary Utilities\initialize.exe [2010-03-04 12:03]
2010-07-18 d:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- d:\programmi\Google\Update\GoogleUpdate.exe [2010-02-16 16:14]
2010-07-19 d:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- d:\programmi\Google\Update\GoogleUpdate.exe [2010-02-16 16:14]
.
.
------- Scansione supplementare -------
.
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - d:\windows\system32\GPhotos.scr/200
IE: E&sporta in Microsoft Excel - d:\progra~1\MI1933~1\Office10\EXCEL.EXE/3000
FF - ProfilePath - d:\documents and settings\GIANNI\Dati applicazioni\Mozilla\Firefox\Profiles\onlxn38i.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - component: d:\programmi\Real\RealPlayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: d:\programmi\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: d:\programmi\Google\Picasa3\npPicasa3.dll
FF - plugin: d:\programmi\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: d:\programmi\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - d:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
d:\programmi\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
d:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
d:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
d:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
d:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
d:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
d:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
d:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
d:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
d:\programmi\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
d:\programmi\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
d:\programmi\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
d:\programmi\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
d:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
d:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
d:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
d:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
d:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
d:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
d:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
d:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
d:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
d:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
d:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
d:\programmi\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-07-20 20:21
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Environment*]
"Licence0"="04F0D21-79D8-7A25-D702-433F"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'winlogon.exe'(696)
d:\windows\system32\Ati2evxx.dll
d:\windows\system32\LMIinit.dll
d:\windows\system32\LMIRfsClientNP.dll
.
Ora fine scansione: 2010-07-20 20:23:09
ComboFix-quarantined-files.txt 2010-07-20 18:23
Pre-Run: 1.423.667.200 byte disponibili
Post-Run: 2.273.828.864 byte disponibili
- - End Of File - - D1E2786224AD975B104A9E2EDCA340F1